CVE-2026-50283 | Craft CMS up to 4.17.13/5.9.20 actionReplaceFile assetToReplace authorization (GHSA-qh45-9g5p-m2v4)
A vulnerability identified as problematic has been detected in Craft CMS up to 4.17.13/5.9.20. Affected by this issue is the function AssetsController::actionReplaceFile. Performing a manipulation of the argument assetToReplace results in missing authorization.
This vulnerability was named CVE-2026-50283. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.VulDB Recent EntriesRead More